The API security problems we have now are not new. Broken object-level authorization–the flaw where your API happily hands over record 1002 to someone who was only ever supposed to see record 1001, because it checked that you were logged in but never checked that the record was yours–has topped the API security lists for years. We have known about it, written about it, and built entire tooling categories around it.
Agents Turn Broken Auth Into a Breach at Machine Speed
calendar_today
August 12, 2026
domain
programmableweb